Privacy Policy
This Privacy Policy explains how PubFi handles information when people use the PubFi website, accounts, APIs, MCP server, and OpenAI Plugin.
Last updated: August 21, 2026
This Privacy Policy explains how PubFi handles information when people use the PubFi website, accounts, APIs, MCP server, and OpenAI Plugin.
Last updated: August 21, 2026
We receive information that visitors choose to provide directly, such as email messages sent to hello@pubfi.ai.
When analytics consent is granted, we may also collect basic website usage information through Google Analytics, including page views, approximate geography, device type, browser information, and referral sources.
PubFi uses Supabase Auth for account sessions. Depending on the sign-in method, we process an email address, provider identity, account subject, session information, and authentication events. PubFi does not store an OAuth access token in its execution-principal records.
When a user links PubFi in ChatGPT or Codex, the OpenAI host completes OAuth and sends the access token with MCP requests. PubFi verifies that token and resolves the accepted identity to one account and execution principal.
PubFi processes the capability, route, method, query, request content, and identifiers needed to authenticate, authorize, meter, route, execute, secure, and support a service request. The selected upstream data provider receives the request fields needed to answer that request.
For a paid Account-lane execution, PubFi persists the execution identity, including the OAuth issuer, client, and account subject when OAuth is used; account, entitlement, allocation, pricing, and usage coordinates; request and idempotency identifiers; canonical route, method, provider, status, and latency; and the exact bounded terminal provider response needed for idempotent replay.
The paid record binds the raw request with SHA-256 and canonical route identity. It does not store the full raw request body as the paid request record. A free execution does not create a paid usage fact or paid terminal replay record. Other account, quota, security, and operational records can still apply.
We use information to provide account access, apply entitlements and free quotas, execute selected data requests, meter paid usage, provide exact idempotent replay, prevent abuse, diagnose faults, respond to support and legal requests, and improve the website and service.
We use submitted contact information to respond to inquiries. We use consented analytics data to understand website traffic and improve site content.
This site displays a cookie and privacy notice before loading Google Analytics. If a visitor declines analytics, Google Analytics will not be loaded in that browser session through this consent flow.
Visitors can clear the relevant browser storage to remove a previous analytics choice and receive the notice again on a future visit.
PubFi does not sell personal information through the website or service. Limited information may be processed by providers that support authentication, hosting, analytics, communications, data delivery, security, or support, subject to their respective terms.
OpenAI processes information under its own terms when a user installs, links, or uses the PubFi Plugin in ChatGPT or Codex. PubFi sends request data to the exact upstream data provider selected through the PubFi capability catalog.
PubFi currently treats paid usage facts and terminal replay records as append-only billing-account and service records. We retain them for the lifetime of the related billing-account or service record; there is no general time-based compactor for those records today.
We may retain information longer when required to comply with law, resolve disputes, enforce agreements, prevent abuse or fraud, maintain security, or preserve financial and audit integrity. These duties can limit a deletion request. Retention for other information depends on its stated purpose and the applicable account, security, provider, and legal requirements.
Users can decline website analytics, sign out, stop making service requests, and disconnect the PubFi Plugin in ChatGPT or Codex. Disconnecting the Plugin stops future Plugin access but does not automatically delete PubFi account, billing, usage, or audit records.
Requests to access, correct, or delete personal information can be sent to hello@pubfi.ai. PubFi will evaluate a request under applicable law, account security, and the retention exceptions described above.
Questions about this Privacy Policy can be sent to hello@pubfi.ai.